Avatar for akkodis
akkodis
Actively Hiring
Digital engineering solutions for industry innovation

Windows Engineer

Posted: 5 days ago• Recruiter recently active
Job Location
Remote Work Policy

In office

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Active Directory
PowerShell
WSUS
Group Policy
Microsoft Intune
Microsoft SCCM
Entra ID
Windows Update for Business
SCCM Software Update Groups

About the job

Akkodis is looking for a Windows Client Engineer to manage and modernize our Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: you'll partner closely with our security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.

Pay Range: $45-50/hour; The rate may be negotiable based on experience, education, geographic location, and other factors.

Job Title: Windows Client Engineer - Endpoint & Vulnerability Remediation

Location: Pittsburgh PA 15212 (Onsite)

Duration: 12-month

Job Description:

What you'll do

• Review outstanding vulnerabilities identified by Tenable (Tenable.io / Nessus / Tenable Security Center) and own the endpoint-side remediation workflow from finding to closure.

• Build, test, and deploy remediation packages and solutions using Intune and SCCM - application updates, patches, registry and configuration changes, and scripted fixes.

• Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items.

• Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC).

• Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate.

• Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives.

• Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs.

• Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet.

• Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment.

• Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production.

What you'll bring:

• 3-5 years of experience engineering and administering Windows endpoints in an enterprise environment.

• Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment.

• Strong PowerShell scripting skills for automation, detection, and remediation.

• Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates).

• Familiarity with vulnerability management concepts and tooling - Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant.

• Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions.

• Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD).

• Ability to test changes carefully and roll out fixes without disrupting end users.

Nice to have:

• Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX.

• Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration.

• Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs).

• Relevant certifications (Microsoft MD-102, SC-200, or CompTIA Security+).

If you are interested in this role, then please click APPLY NOW. For other opportunities available at Akkodis, or any questions, feel free to contact me at [email protected]

Equal Opportunity Employer/Veterans/Disabled

Benefit offerings available for our associates include medical, dental, vision, life insurance, short-term disability, additional voluntary benefits, an EAP program, commuter benefits, and a 401K plan. Our benefit offerings provide employees the flexibility to choose the type of coverage that meets their individual needs. In addition, our associates may be eligible for paid leave including Paid Sick Leave or any other paid leave required by Federal, State, or local law, as well as Holiday pay where applicable. Disclaimer: These benefit offerings do not apply to client-recruited jobs and jobs that are direct hires to a client.

To read our Candidate Privacy Information Statement, which explains how we will use your information, please visit https://www.akkodis.com/en/privacy-policy.

The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:

· The California Fair Chance Act

· Los Angeles City Fair Chance Ordinance

· Los Angeles County Fair Chance Ordinance for Employers

· San Francisco Fair Chance Ordinance

Similar Jobs

Gray Swan AI company logo
Gray Swan AI
We are a RAPID growth AI startup safeguarding AI models from evolving security threats